Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Installation

Requirements

  • Node.js 20 or newer.
  • sigsum-submit must be available on your $PATH for manifest sign operations. (See Installing the CLI below.)
  • A Sigsum trust policy and keypair for signing manifests.
  • An OIDC identity token in the environment (CI-supported) or interactive login for manifest sign --type sigstore.

Installing the CLI

npm install @freedomofpress/webcat-cli

To run the installed CLI:

npx webcat --help

Sigsum needs to be installed separately, as it currently is only available in Go binaries. Install Go if needed, then:

go install sigsum.org/sigsum-go/cmd/sigsum-key@latest
go install sigsum.org/sigsum-go/cmd/sigsum-submit@latest

By default, these binaries will be available in $HOME/go/bin.

Using the CLI

Once installed, you can use the CLI and sigsum for manual signing of your web assets manifest.

Or, to learn more details on the sub-commands within the CLI, check the enrollment, mainfest, and bundle command references.